Skip ahead to the guide
Pescadores Galapagos Tech HubHands-on tech desk
Desk updated
how-tos
48
Desk sections
10
Browse the desk
  1. Technology
  2. Apps
  3. Travel
  4. Insurance
  5. Business
  6. Small business
  7. Corporate
  8. Home & Garden
  9. Real estate
  10. Gardening
  11. Media & Design
  12. Social Media
  13. Creative
  14. About
  15. How It Works
  16. Contact

Cyber Insurance for Small Business: What a Policy Can Cover

Sits under
Insurance
Posted
Read time, roughly
4 min
Home office, work from home and computer
Image 39 Home office, work from home and computer

Cyber insurance for a small business is a policy that helps pay for the costs of a data breach, ransomware attack or similar digital incident. It usually has two halves: first-party cover for the business's own losses, such as investigating the attack and restoring systems, and third-party or liability cover for claims brought by customers, partners or, where the law allows, regulators. What a specific policy pays depends entirely on its wording, its limits and the security measures the business promised to keep in place.

Why small firms look at it at all

Small businesses hold the same kinds of sensitive information as larger ones: customer names and addresses, card payments, staff records and supplier invoices. They also tend to have fewer people to notice a problem early. A shop that has opened on a limited budget often runs its till, bookings and email through a handful of online accounts, and losing access to any of them for a week can hurt as much as the theft itself. General business insurance frequently excludes or limits cyber events, which is why a separate policy or an add-on exists.

The two halves of a policy

First-party cover (your own costs)Third-party cover (claims against you)
Forensic investigation to find out what happenedLegal defence if customers or partners sue over exposed data
Restoring data and rebuilding affected systemsSettlements or damages, within the policy limit
Business interruption: lost income while systems are downRegulatory investigations, where insurable under local law
Notifying affected people and offering support such as credit monitoringMedia liability, for example claims over content published online
Extortion or ransomware response, subject to the policy and the lawPayment card industry assessments, on some policies

Many policies also include access to an incident response line and a panel of specialists, such as lawyers, forensic investigators and communications advisers, who can be called the moment something goes wrong. For a business without its own IT department, that support can be as valuable as the money.

Common exclusions and limits

  • Known incidents. Breaches discovered or suspected before the policy started are normally excluded.
  • Broken promises. If the application said backups are tested and multi-factor authentication is on, and they were not, a claim can be reduced or refused.
  • Upgrades. Policies typically pay to restore systems to how they were, not to buy better ones.
  • Social engineering fraud. Losses from staff being tricked into sending money are often covered only through a specific extension, sometimes with a low sublimit.
  • Physical harm and property damage. These usually belong to other policies.
  • Large-scale events. War and infrastructure exclusions appear in many wordings and are worth reading slowly.

The security questions insurers ask

Applying for cyber cover is partly a security review. Insurers commonly ask whether the business uses multi-factor authentication for email and remote access, keeps regular backups stored separately from the main systems, installs software updates promptly, trains staff to spot phishing and limits who has administrator rights. The answers affect both the price and whether cover is offered.

Writing those habits down helps twice: once when filling in the form, and again when an incident happens and everyone needs to know their part. A short, numbered standard operating procedure for backups, password resets and reporting suspicious emails turns good intentions into routine. Keeping records accurate and tamper-evident matters too, a theme that runs through discussions of data integrity in newer systems.

What to compare between quotes

  1. Overall limit and sublimits. A generous headline limit can hide small sublimits for ransomware, business interruption or fraud.
  2. Retention or excess. The amount the business pays before cover begins, and whether business interruption has a waiting time measured in hours.
  3. Retroactive date. Some policies cover incidents that began before the start date but were found later; others do not.
  4. Notification rules. How quickly an incident must be reported, and to whom.
  5. Choice of specialists. Whether you must use the insurer's panel or can bring your own advisers.
  6. Definitions. What counts as a computer system, including cloud services and staff-owned devices.

Questions owners often ask

Does a very small business really need cyber insurance?

It depends on how much the business relies on data and online systems and what its other policies already include. Comparing the cost of a few days offline with the premium is a sensible starting point, and a licensed broker can explain what existing policies already cover.

Is cyber insurance the same as cyber liability insurance?

The terms are often used loosely. Strictly, liability refers to the third-party half. Many small-business policies bundle both halves, but some sell them separately, so check which one a quote includes.

Will insurance replace good security?

No. Insurers expect basic controls to be in place, and a policy cannot restore customer trust on its own. It is a financial backstop for when sensible precautions are not enough.

This is a general explanation, not advice on any specific policy. Cover, exclusions and legal limits differ between insurers and countries, so speak with a licensed broker or adviser before buying.

08

Nearby in this section